Nadoo Cloud

Nadoo Cloud Privacy Policy

How Nadoo Cloud processes and protects personal data, and how customers can exercise their rights.

Article 1. Purposes of Processing Personal Data

  1. Account registration, identity verification, organization and user management, and account security
  2. Service provision, operation of instances and resources, customer support, incident response and security monitoring
  3. Fee calculation, payment, issuance of tax invoices, management of unpaid amounts and accounting
  4. Prevention of misuse, investigation of Terms violations, fulfillment of statutory obligations and dispute handling
  5. Service improvement, statistical analysis, delivery of notices and handling of customer inquiries

Article 2. Categories of Personal Data Processed

The Company processes only the personal data necessary to provide the services. The categories processed may vary depending on the registration method, payment method, organization settings, services used, support requests and connected services.

  1. Account information: name, email address, password, organization, job role and telephone number
  2. Contract and payment information: company name, business registration number, contact person details, payment records, billing and tax invoice information
  3. Service usage information: login records, IP addresses, device and browser information, API call records, instance and resource usage, and event logs
  4. Customer support information: inquiries, attachments, consultation history and incident handling records
  5. Personal data contained in data uploaded directly by the customer or processed in its workloads

Article 3. Retention and Use Periods

The Company retains and uses personal data until the processing purpose is fulfilled, the service contract is terminated, the account is closed, consent is withdrawn or the statutory retention period expires. Where retention is necessary for statutory obligations, dispute handling, security, audits or settlement, the data may be stored separately for the relevant period.

Article 4. Third-Party Disclosure and Outsourced Processing

The Company does not disclose personal data to third parties except with the data subject's consent or as permitted by law. The Company may outsource some tasks necessary for providing the services to specialist providers. When entering into outsourcing agreements, the Company manages and supervises processors to ensure that personal data is handled securely in accordance with applicable law.

Article 5. International Transfers

Personal data may be transferred outside the Republic of Korea when the Company uses overseas cloud, payment, email delivery, customer support, monitoring or other overseas processors. Where an international transfer occurs, the Company discloses the destination country, recipient, data categories, purpose, retention period and method of refusing the transfer, or obtains the necessary consent, as required by applicable law.

Article 6. Data Subject Rights

  1. Data subjects may exercise rights of access, correction or deletion, restriction of processing, withdrawal of consent, account closure and other rights provided by applicable law.
  2. Rights may be exercised through account settings in the service, customer support channels or the contact details of the person responsible for personal data protection.
  3. The Company handles requests to exercise rights within the periods and under the procedures prescribed by applicable law.
  4. All or part of a request may be restricted where there is a statutory retention obligation, a risk of infringing another person's rights, or grounds necessary for service security or contractual performance.

Article 7. Automated Decisions

The Company may use automated analysis or rule-based measures for security, prevention of misuse, protection of resources, payment risk management and service stability. If a measure constitutes an automated decision under the Republic of Korea's Personal Information Protection Act and significantly affects a data subject's rights or obligations, the data subject may request an explanation, refuse the decision or request a review in accordance with applicable law.

Article 8. Automatic Collection Technologies

The Company may use cookies, similar technologies and log collection tools to maintain login sessions, provide security, improve service quality and perform statistical analysis. Users may refuse or delete cookies through browser settings, but doing so may limit the use of some features.

Article 9. Security Measures

  1. Access permission management, least-privilege principles, access reviews and training for personnel handling personal data
  2. Encryption, retention of access records, detection of anomalous activity, vulnerability checks and security patches
  3. Backup, recovery, incident response, security incident procedures and physical access controls
  4. Management and supervision of processors and reviews of personal data processing

Article 10. Inquiries and Policy Changes

Inquiries concerning access, correction or deletion, restriction of processing, complaints and remedies may be submitted to the personal data protection contact and customer support contacts indicated by the Company in the service interface or on its website.

The Company may amend this Privacy Policy following changes in law, services, processors, processing purposes or internal policies. Important changes will be notified before taking effect through reasonable means such as the service interface, website or email.